Key Takeaways
- Shopify completed a three-step WhatsApp build-out in under eight weeks: consent on the customer profile (17 June 2026), WhatsApp campaigns inside Shopify Messaging (29 July 2026), and consent capture on Shopify Forms (6 August 2026). None of the three announcements mentions GDPR, ePrivacy, or what a valid opt-in looks like.
- The 17 June release ships a bulk import tool to "add consent from an existing subscriber list." Carrying an email or SMS opt-in across to WhatsApp that way is the fastest route to consent you cannot defend — the EDPB treats conflated purposes as a failure of granularity (Guidelines 05/2020, para 44).
- Meta's rules and the law are two separate tests. The WhatsApp Business Messaging Policy requires an opt-in, then says: "You are solely responsible for determining the method of opt-in, that you have obtained opt-in in a manner that complies with laws applicable to your communications."
- The UK's PECR defines "electronic mail" by function — a message that "can be stored... until it is collected by the recipient" — and the only technology it names is SMS. No EU or UK regulator has published WhatsApp-specific marketing guidance that we could locate, so the conservative read is that regulation 22's prior-consent rule applies.
- Shopify's documented consent fields record state, opt-in level, source and timestamp. None of them stores the wording shown to the customer — which is precisely what the EDPB says must be demonstrable (para 108).
Introduction
Your growth lead saw the changelog before you did. On 6 August 2026 Shopify announced that WhatsApp marketing consent can now be collected on Shopify Forms, and somewhere in your Slack there is now a message proposing you switch it on before Q4.
The feature does exactly what it says. What it does not come with is a consent standard. None of Shopify's three WhatsApp releases this summer mentions GDPR, ePrivacy, or what a lawful opt-in looks like — that part is yours. And the most tempting shortcut, pouring your existing email list into the new WhatsApp consent field, is the one most likely to leave you with a subscriber list you cannot defend.
This guide covers what Shopify shipped, why a WhatsApp opt-in is its own consent rather than an extension of an existing one, and what to record to prove it.
This article is informational content, not legal advice. ePrivacy rules are transposed nation by nation and the specifics vary — confirm your position with a qualified professional.
What Shopify's WhatsApp Marketing Consent Field Does — and Doesn't Do
Shopify's WhatsApp consent field records that a customer opted in, when, and from where. It does not test whether the opt-in was lawful, does not distinguish WhatsApp consent from email or SMS consent in legal terms, and does not capture what the customer was shown. The compliance layer is entirely yours to build.
Three releases, in sequence:
| Date | What shipped | Compliance guidance included |
|---|---|---|
| 17 June 2026 | WhatsApp consent "directly in each customer's profile in Shopify, alongside email and SMS consent", plus a bulk import/export tool | None |
| 29 July 2026 | WhatsApp marketing as a Shopify Messaging channel, with templates, interactive buttons and keyword replies | None |
| 6 August 2026 | Consent capture on Shopify Forms — "Capture opt-ins when customers fill out a form on your store" | None |
The developer surface landed alongside the June release: a customerWhatsAppMarketingConsentUpdate mutation and a whatsAppMarketingConsent field on the customer's phone-number object, in both the Admin API and the Customer Account API. Shopify's merchant help documentation now lists three marketing-consent channels — email, SMS and WhatsApp — and frames the merchant's job as recording consent, pointing elsewhere for data-protection matters.
The bulk-import trap
The June announcement's convenience feature is the compliance risk. It offers to "save time using the bulk import and export tool to add consent from an existing subscriber list" — and an existing subscriber list, for almost every store, means the email or SMS list.
Do not do this. It is the single worst thing you can do with the new field, because it manufactures a consent record for a channel the customer never agreed to, and it does so at list scale. Recital 32 GDPR is direct: "Consent should cover all processing activities carried out for the same purpose or purposes. When the processing has multiple purposes, consent should be given for all of them." The EDPB's worked example is uncomfortably close to home — in Guidelines 05/2020 it says a retailer asking in one request to send email marketing and share details with group companies has consent that "is not granular as there is no separate consents for these two separate purposes, therefore the consent will not be valid" (para 45).
The trade-off is real and worth naming: rebuilding a WhatsApp list from zero is slower than importing one. It is also the only version you can produce under audit.
Is a WhatsApp Opt-In the Same as Your Email Opt-In?
No. An email opt-in is consent to receive email; it is not consent to receive messages on a different channel, at a different address, with different intrusiveness. Under Article 4(11) GDPR consent must be "specific", and the EDPB reads specificity to require separating purposes and "obtaining consent for each purpose" (Guidelines 05/2020, para 44).
The practical test is what the customer would have understood at the moment they ticked the box. Someone who entered an email address under a line about "news and offers" agreed to email. They did not agree to a message arriving in the same app as their family group chat, on a number they gave you to arrange a delivery.
What granularity means when you add a channel
Granularity is not a style preference; the EDPB frames its absence as a defect in the freedom of consent. Para 44 is explicit: "If the controller has conflated several purposes for processing and has not attempted to seek separate consent for each purpose, there is a lack of freedom."
There is a further trap in reusing old consent even on the same channel. The EDPB notes there is no fixed expiry for consent, but that "if the processing operations change or evolve considerably then the original consent is no longer valid" and new consent must be obtained (para 110). Adding an entirely new messaging channel to the purposes a customer signed up for is, on any reasonable reading, a considerable evolution.
Two Tests, Not One: Meta's Policy and the Law
Meta's WhatsApp Business Messaging Policy and EU/UK law both require an opt-in, but they are not the same test and passing one does not pass the other. Meta's policy governs whether your WhatsApp Business account stays open; the law governs whether you may lawfully send the message.
Meta sets the platform floor: "You may only contact people on WhatsApp if: (a) they have given you their mobile phone number; and (b) you have received opt-in permission from the recipient confirming that they wish to receive subsequent messages or calls from you." It then hands the legal question straight back to you — "You are solely responsible for determining the method of opt-in, that you have obtained opt-in in a manner that complies with laws applicable to your communications." It also requires you to honour opt-outs raised anywhere: "You must respect all requests (either on or off WhatsApp) by a person to block, discontinue, or otherwise opt out of communications from you via WhatsApp."
| Question | Meta's Business Messaging Policy | GDPR / ePrivacy |
|---|---|---|
| Is an opt-in required? | Yes — phone number plus opt-in permission | Yes — prior consent for direct marketing by electronic mail, subject to the soft opt-in below |
| Is the opt-in method prescribed? | No — expressly the business's responsibility | Consent must be freely given, specific, informed, unambiguous (Art. 4(11)) |
| Must consent be granular? | Separate opt-ins per message category recommended as best practice | Required where purposes differ (EDPB paras 44–45) |
| Must you be able to prove it? | Not specified | Yes — Art. 7(1): the controller "shall be able to demonstrate" consent |
| Consequence of failure | Account restriction | Regulatory action under national ePrivacy rules and the GDPR |
Read that fourth row twice. Meta never asks you to keep evidence. Article 7(1) does, and it is the row that decides how an investigation goes.
Does the ePrivacy Soft Opt-In Cover WhatsApp?
Possibly, but only if every condition is met, and no regulator has confirmed the channel. The UK's PECR regulation 22(3) requires that you obtained the details during a sale or sale negotiations, that the marketing covers "similar products and services only", and that an easy refusal was offered at collection and in every message since.
Start with what "electronic mail" means, because that is what regulation 22 governs. PECR defines it as "any text, voice, sound or image message sent over a public electronic communications network which can be stored in the network or in the recipient's terminal equipment until it is collected by the recipient and includes messages sent using a short message service." That is a functional definition — a stored text message collected by the recipient — and it names no technology except SMS. PECR separately defines direct marketing as "the communication (by whatever means) of advertising or marketing material which is directed to particular individuals."
Here is where honesty matters more than confidence. No EU or UK data protection authority has published guidance naming WhatsApp or messaging apps in a marketing-consent context that we could locate. France's CNIL states the rule as "La publicité par voie électronique (courrier électronique, SMS-MMS, automate d'appel, etc.) est possible à condition que les personnes aient donné leur consentement avant d'être démarchées" — electronic advertising requires consent before contact — listing channels that end in "etc." rather than an exhaustive set. CNIL's existing-customer exception turns on "produits ou services similaires" from the same company, and CNIL notes that merely creating an online account does not qualify as the prior sale that unlocks it.
Our read: the soft opt-in is a defensible position for order-adjacent messages to genuine past purchasers about similar products, and a bad bet for prospect lists, lead-gen contacts, or anyone who only ever created an account. Where you rely on it, document the reasoning, the source of the number, and the refusal mechanism at each step — because the exemption is a set of conditions you must evidence, not a category you can assert.
What to Log to Prove a WhatsApp Opt-In
Log what the customer saw, not just that they agreed. The EDPB expects a controller to keep "a record of consent statements received, so he can show how consent was obtained, when consent was obtained and the information provided to the data subject at the time shall be demonstrable" — and to show that "the controller's workflow met all relevant criteria for a valid consent" (para 108).
Compare that against the fields Shopify documents on its WhatsApp consent object: collectedFrom ("The source from which the marketing consent was collected"), updatedAt ("The date and time when the marketing consent was updated"), sourceLocation ("The location where the customer consented to receive marketing material"), optInLevel, and state. Useful metadata, all of it — and not one field for the sentence the customer actually read. That is the gap you fill yourself.
A defensible WhatsApp consent record:
- Who — the customer or session identifier, tied to the phone number that was opted in.
- When — an ISO-8601 timestamp of the affirmative act.
- What they were told — the exact consent wording plus the privacy-notice version, stored as a versioned snapshot rather than a live link.
- How — which form, which checkbox, which flow; a WhatsApp-specific control, not a shared marketing toggle.
- What for — WhatsApp marketing recorded as its own purpose, separate from email and SMS.
- Withdrawal state — whether they later opted out, when, and through which route, including "stop" replies and blocks handled off-platform.
Keep the evidence append-only, and keep it after the customer data goes: the EDPB says proof "should be kept no longer then strictly necessary for compliance with a legal obligation or for the establishment, exercise or defence of legal claims" under Article 17(3)(b) and (e) (para 107). Our full treatment of that retention question is in the guide to proof of consent records.
Your WhatsApp List in the RoPA — and What Erasure Means
A WhatsApp subscriber list is a new processing activity on a new lawful basis, and it needs its own entry in your record of processing. A mobile number is personal data on the face of Article 4(1) GDPR, which treats any information relating to an identifiable person as personal data and names "an identification number" among the identifiers that make a person identifiable.
Four things change the moment you switch the channel on, and none of them is cosmetic:
- A new purpose and lawful basis. WhatsApp marketing is not covered by whatever entry currently describes your email programme. Add it explicitly, with its own basis and retention period, in your record of processing activities.
- A new recipient. Messages route through Meta's infrastructure and, for most stores, a business solution provider on top of it. Both belong in the RoPA and in your privacy notice.
- A wider access request. A subject access request now has to reach the WhatsApp consent state and the message history, not just Shopify's customer record and your ESP.
- A harder erasure. Removing someone from your list is the easy half; the number and conversation also sit in the messaging stack. Decide in advance what "erased" means across every system holding it, and write that down before the first campaign, not during the first request.
One distinction is worth holding onto, because it is easy to conflate: the rules in this article govern sending marketing messages, a different legal question from the browser-side consent that governs tracking on your storefront. Those terminal-equipment rules are covered in our guide to the 26 August 2026 web pixel consent deadline.
How to Switch WhatsApp Marketing On Without Breaking Consent
- Start the WhatsApp consent state at zero, whatever the import tool offers.
- Add a dedicated, unticked WhatsApp checkbox to the Shopify Form, with its own sentence — never a sub-clause of a general marketing opt-in.
- Name the channel and the sender. "Yes, send me offers from [store] on WhatsApp" is specific. "Subscribe to marketing" is not.
- Version and snapshot that wording, so you can reproduce what a customer saw on a given date rather than what the form says today.
- Wire opt-out both ways. Honour "stop" replies and blocks inside WhatsApp and reflect them back into the Shopify consent state, since Meta requires you to respect requests raised "either on or off WhatsApp."
- Re-permission instead of assuming. To move your existing email list onto WhatsApp, ask on the channel they already consented to and treat the reply as the new consent.
Common Mistakes
Importing the email list into the WhatsApp consent field. The worst of the set, because it scales. It creates a consent record for a purpose the customer never agreed to, and the record's existence makes the problem look solved.
Treating Meta's approval as legal clearance. Your templates being approved and your account staying open tells you that you satisfied Meta. The policy itself says the legal method of opt-in is "solely" your responsibility.
Reading an inbound message as marketing consent. A customer messaging you about a delayed parcel has started a service conversation. Nothing in that act is a freely given, specific, informed indication of agreement to receive promotions.
Bundling the opt-out. Under Article 7(3) withdrawal must be "as easy to withdraw as to give consent." If opting in took one tap in a form and opting out takes an email to support, the asymmetry is the finding.
Leaving WhatsApp out of the RoPA. New channel, new processors, new data flow. A record of processing that still describes only email and SMS is out of date the day the first campaign sends — and it is the first document a regulator asks for. For the wider programme this sits inside, see our complete guide to GDPR compliance.
How PrivacyForge Helps
The hard part of adding a marketing channel is not the toggle; it is that one new channel touches four systems at once. PrivacyForge is built around that shape.
Consent records are stored per purpose, with the wording versioned and snapshotted at the moment of capture, so a WhatsApp opt-in is a distinct, reproducible record rather than a flag sitting next to email. The data-mapping module gives the new activity its own RoPA entry, with Meta and your business solution provider recorded as recipients. When an access or erasure request arrives, the DSAR workflow reads from that map, so the WhatsApp consent state is in scope from the start rather than remembered late.
None of this decides your legal position for you. It makes the position you take evidenceable, which is the part regulators actually ask about.
Frequently Asked Questions
Does my email marketing opt-in cover WhatsApp?
No. Consent must be specific under Article 4(11) GDPR, and the EDPB requires separating purposes and obtaining consent for each one (Guidelines 05/2020, para 44). An email opt-in evidences agreement to receive email. Collect a separate, clearly worded WhatsApp opt-in, and record it as its own purpose rather than reusing the existing marketing flag.
Is Meta's WhatsApp opt-in requirement the same as GDPR consent?
No — they are two separate tests. Meta's WhatsApp Business Messaging Policy requires a phone number and opt-in permission, then states that you are "solely responsible for determining the method of opt-in" in a way that "complies with laws applicable to your communications." Meta's approval keeps your account open; it does not establish a lawful basis under GDPR or national ePrivacy rules.
Can I use the ePrivacy soft opt-in for WhatsApp marketing?
Only if every condition is met, and no regulator has confirmed the channel. The UK's PECR regulation 22(3) requires that you obtained the details during a sale or sale negotiations, that the marketing covers similar products and services only, and that a simple refusal option was offered at collection and in each message. Prospect lists do not qualify, and CNIL's position is that creating an account is not itself a sale.
Does a customer messaging me first count as consent to send marketing?
No. An inbound message opens a service conversation; it is not a freely given, specific and informed indication of agreement to receive marketing, as Article 4(11) GDPR requires. Treat service replies and marketing as separate purposes, and collect an explicit marketing opt-in before sending promotional content on the channel.
What do I need to record to prove a WhatsApp opt-in?
Record who consented, when, exactly what wording they were shown, how they signalled agreement, the specific purpose, and any later withdrawal. The EDPB expects "the information provided to the data subject at the time" to be demonstrable (Guidelines 05/2020, para 108). Shopify's consent fields capture state, source and timestamp — but not the wording, so store that yourself.
Conclusion
In the 50 days to 6 August 2026 Shopify made WhatsApp marketing a two-click channel and left the consent standard to you. That is not an oversight to complain about; it is the ordinary division of labour between a platform and a controller, and it is the same division that produced years of poorly evidenced email lists.
The decision in front of you is narrow. You can import an existing subscriber list into the new consent field and have a WhatsApp programme running this week, or you can collect channel-specific opt-ins and have one you can defend. Only the second one survives a request to produce the evidence — and given how recently the field appeared, most of your competitors are about to pick the first.
Start with the consent record, not the campaign. If you want to see what per-purpose consent records and a RoPA that keeps pace with a new channel look like in practice, explore PrivacyForge.
Sources
- Shopify changelog — Collect WhatsApp marketing consent on Shopify Forms (6 August 2026)
- Shopify changelog — Shopify Messaging now supports WhatsApp marketing (29 July 2026)
- Shopify changelog — Manage WhatsApp marketing consent in Shopify (17 June 2026)
- Shopify developer changelog — WhatsApp marketing consent in the Admin API and Customer Account API
- Shopify Admin GraphQL — CustomerWhatsAppMarketingConsent fields
- Shopify Admin GraphQL — CustomerPhoneNumber
- Shopify Help Center — Customer marketing consent
- WhatsApp Business Messaging Policy
- EDPB Guidelines 05/2020 on consent under Regulation 2016/679 (Version 1.1, adopted 4 May 2020)
- GDPR Article 4 — Definitions
- GDPR Article 7 — Conditions for consent
- GDPR Recital 32 — Conditions for consent
- PECR 2003, regulation 2 — Interpretation
- PECR 2003, regulation 22 — Use of electronic mail for direct marketing purposes
- CNIL — La prospection commerciale par courrier électronique